Question 4 of 10Pro Only
How do you conduct a threat model for a new system, and what frameworks do you use?
Sample answer preview
Threat modeling is a structured approach to identifying, categorizing, and prioritizing security threats to a system. It should be conducted during the design phase, before vulnerabilities are built into the architecture, and updated as the system evolves.
threat modelingSTRIDEDREADtrust boundariesattack surfacedata flow diagram